VYPR
High severity7.8NVD Advisory· Published Feb 16, 2023· Updated Jun 17, 2026

CVE-2023-25602

CVE-2023-25602

Description

A stack-based buffer overflow in Fortinet FortiWeb 6.4 all versions, FortiWeb versions 6.3.17 and earlier, FortiWeb versions 6.2.6 and earlier, FortiWeb versions 6.1.2 and earlier, FortiWeb versions 6.0.7 and earlier, FortiWeb versions 5.9.1 and earlier, FortiWeb 5.8 all versions, FortiWeb 5.7 all versions, FortiWeb 5.6 all versions allows attacker to execute unauthorized code or commands via specially crafted command arguments.

Affected products

3
  • Fortinet/Fortiweb3 versions
    cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:fortinet:fortiweb:*:*:*:*:*:*:*:*range: >=5.6.0,<5.9.2
    • (no CPE)range: <=6.4, <=6.3.17, <=6.2.6, <=6.1.2, <=6.0.7, <=5.9.1, all versions of 5.8, all versions of 5.7, all versions of 5.6
    • (no CPE)range: 6.4.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.